LiveAI agent safetyRuns in your browser

Skill safety check

Is this AI agent skill safe to install?

Paste a SKILL.md or drop a skill folder or zip to see hidden instructions, risky commands, requests for secrets and what the skill may do on your computer, checked with the same rules Hopper Labs runs on its own skills.

Updated

The skill safety check reporting serious problems in a made-up risky skill, with tiles for serious problems, items to review, files and the release gate

What it measures

Hidden instructions

Invisible characters, encoded blobs and phrasing that tries to override an agent or keep you out of the loop.

Risky commands and secrets

Commands that download and run code or delete files, and requests for passwords, keys or recovery phrases.

What it may do

Tools it may use without asking, scripts it may run, and whether it reaches the internet, installs software or changes files.

The skill format

The Agent Skills rules for SKILL.md: a valid name that matches the folder, a description, readable text files.

How to use it

  1. Open the lab. Paste a SKILL.md, drop the skill's folder or zip, or try one of the examples.
  2. Read the verdict and the four tiles, then the list of what the skill may do.
  3. Go through the serious problems and the parts worth reviewing. Each one names the file and line.
  4. Install only if you are happy with every item. Copy the report to share it or ask for advice.
Open the lab

Good to know

  • It reads files; it never runs them. A script can still do things the text does not reveal, so read any script before installing.
  • It spots common patterns. A clean result is a good sign, not a guarantee.
  • Links to other sites are flagged for review because what they point to can change after you check.

Give your agent this skill

Try the lab, then let your AI agent keep what it teaches. Read the skill first; install it only if you want to.

What we found

We checked all 19 skills in Anthropic's public skills repository with the lab. None hides instructions or asks an agent to work behind its person's back; the flags are links, scripts, fonts and three lines in documentation examples.

Measured
Hidden instructions
None in 19 skills
No invisible characters, encoded blobs or instruction-hijacking phrasing in any file.
Links to other sites
All 19 skills
1,338 links in total, many of them XML schema addresses in the document skills. Worth a look: what a link points to can change after review.
Scripts
10 of 19 skills
197 script files, mostly in the document skills. An agent may run them, so read them before installing.
Files that are not text
3 skills
54 fonts in canvas-design, a PDF in theme-factory and a .tar.gz archive in web-artifacts-builder. Fonts suit a design skill; an archive hides its contents from review.
skill-creator's report template
Reaches the internet
Its HTML report loads Google Fonts when opened, which tells Google the report was viewed.
Serious flags read by hand
3 harmless
An eval mentioned in prose and an rm -rf inside a tool-call example (claude-api), and a sample prompt asking for an API key (mcp-builder). All are examples, not instructions.

Method: The lab's checks (the same rules as our release gates) run on every file of github.com/anthropics/skills at commit 3337550 (24 September 2026), then each serious flag read by hand.

How-to

Skills (folders with a SKILL.md file) teach AI agents such as Claude, Codex, Cursor and Gemini CLI how to do a job. Your agent follows them later without re-reading them with you, so a bad skill can quietly change what your agent does. Check each one before installing it.

Check a skill

  1. Get the exact files you are about to install: download the skill's folder or zip, or open its SKILL.md. Use a fixed version, not whatever is "latest".
  2. Open the Skill safety check and drop the folder or zip in, or paste the SKILL.md.
  3. Read the verdict:
    • Don't install this as it is: there is at least one serious problem, such as hidden characters, instructions to keep you out of the loop, a request for passwords, or a command that downloads and runs code.
    • Read the flagged parts first: links, scripts, broad tools or files that are not text. These are common in good skills too; make sure each one fits what the skill is for.
    • No problems found: a good sign, not a guarantee. Skim the text anyway.
  4. Check What it may do. A skill for writing meeting notes has no reason to run commands or reach the internet.

Read the scripts

The lab reads files; it never runs them. If a skill includes scripts, open each one and look at what it reads, writes, deletes and connects to, or ask someone you trust to.

Let your agent do the review

Give your agent the Review a skill before installing skill. Before installing any skill or plugin, it works through the same checklist, reports what it found in plain words, and waits for your yes.

What we check our own skills with

The lab uses the same rules as the release gates that every Hopper Labs skill must pass before it is published, so you can hold us to the same standard.

Check that it's private

This lab runs entirely in your browser and sends nothing anywhere. You don't have to take our word for it:

  1. The browser enforces it. This site's security policy only lets pages talk to lab.hopperlabs.ai. This command shows connect-src 'self':curl -sI https://lab.hopperlabs.ai/labs/skill-safety-check/run | grep -i content-security-policy
  2. Every file is listed with its fingerprint and source commit in privacy.json, so you or your agent can compare them and read the code.
  3. Once the lab has loaded, turn off Wi-Fi: it keeps working, because it needs nothing from the network.

This page sends nothing anywhere. If an AI agent or browser extension is reading your screen, it can see what's shown here.

More labs

All labs